Auditbeat Modules
*Note: Not all OS supports all the module options. 1. Auditd - module: auditd resolve_ids: true failure_mode: silent backlog_limit: 8192 rate_limit: 0 include_raw_message: false include_warnings: false backpressure_strategy: auto 2. File Integrity Monitoring - module: file_integrity paths: - /bin - /usr/bin - /sbin - /usr/sbin - /etc exclude_files: - '(?i)\.sw[nop]$' - '~$' - '/\.git($|/)' include_files: [] scan_at_start: true scan_rate_per_sec: 50 MiB max_file_size: 100 MiB hash_types: [sha1] recursive: false 3. System - module: system datasets: - host - login - package - process - socket - user period: 10s state. period: 12h socket. include_localhost: false user. detect_password_changes: true